33. An administrator is investigating a zero-day vulnerability on a core system. If the vulnerability is not patched, the negative impact to business could be significant. The vendor has released a patch, but it requires downtime to deploy. Which of the following actions should the administrator take?
Answer: B
Implement an emergency change.
To address the zero-day vulnerability effectively, the administrator should implement an emergency change. This allows for the rapid deployment of the vendor's patch to mitigate the risk associated with the vulnerability, minimizing potential negative impacts on the business.
A) Create a standard change request.
Creating a standard change request would not be appropriate in this scenario as it typically follows a longer approval process, which could delay the necessary patch deployment. Given the urgency of a zero-day vulnerability, waiting for a standard change procedure may expose the system to significant risk.
B) Implement an emergency change.
Implementing an emergency change is the most suitable action in this context. It allows the administrator to quickly apply the vendor's patch to address the critical vulnerability, thereby protecting the system from potential exploitation and reducing the risk of significant negative business impacts.
C) Immediately freeze all changes.
Freezing all changes is counterproductive when a critical vulnerability is present and a patch is available. While this option may seem cautious, it would leave the system vulnerable rather than addressing the immediate threat posed by the zero-day vulnerability.
D) Continue operations until the next change interval.
Continuing operations until the next change interval is not advisable, especially with an active zero-day vulnerability. This option would allow the vulnerability to remain unaddressed, potentially leading to severe repercussions for the business, which contradicts the need for immediate action.
Conclusion
Implementing an emergency change is the definitive right choice as it prioritizes the urgent need to patch a critical vulnerability. All other options either delay necessary action or leave the system exposed, which could result in significant adverse effects on the business. Immediate deployment of the patch is essential to safeguard against potential threats.